Session

The Invisible Weak Link: Inside Modern Software Supply Chain Attacks

Last week, LiteLLM a Python library downloaded 95 million times a month was silently compromised through an attack that first weaponized a security scanner. In 2021, Log4j sent every tech company into emergency mode. In 2020, SolarWinds exposed 18,000 organizations including multiple government agencies. These are not isolated incidents. They are symptoms of a systemic crisis: the software that runs modern life is assembled from thousands of open-source ingredients, and attackers have learned that poisoning the supply is far more efficient than breaking through the front door.

In this session, you will learn how modern supply chain attacks actually work from dependency confusion and typo-squatting to CI/CD pipeline compromise and credential cascading. Using real-world case studies from 2024–2026, we will dissect the anatomy of these attacks, understand why they are getting worse (deeper dependency trees, AI coding assistants recommending popular but unvetted packages, and an explosion in open-source consumption), and explore the automated defense strategies that organizations can deploy today. Attendees will leave with a concrete framework for assessing their own supply chain exposure and actionable steps to reduce it.


Format: Session Presentation (30 min) or Keynote (45 min)
Level: Introductory to Intermediate

Ankit Kumar Honey

Engineering leader securing the world's software supply chain at GitHub (Microsoft). MS Data Science candidate at Harvard. Building AI-driven defences for 180M+ developers.

Seattle, Washington, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top